Proving Grounds / OSCP Practice
Walkthroughs focused on training-lab enumeration, initial access, privilege escalation, and reusable offensive-security lessons.
LAB WALKTHROUGHS
Technical walkthroughs of security labs and training-platform machines, focused on enumeration, exploitation, privilege escalation, and practical lessons.
Browse published writeups by focus area.
Walkthroughs focused on training-lab enumeration, initial access, privilege escalation, and reusable offensive-security lessons.
Walkthroughs of web and API security labs covering vulnerability discovery, exploitation, and practical attack paths.
Walkthroughs of Android and iOS security labs covering application analysis, exploitation, and mobile-specific attack techniques.
A Proving Grounds Linux walkthrough covering virtual-host discovery, default control-panel credentials, FTP access to application source code, a hidden environment file exposing reusable credentials, SSH access as spidey, and privilege escalation through a writable systemd service with limited passwordless systemctl permissions.
An exposed rConfig instance was taken over through an administrator password reset, then leveraged through an upload-validation bypass to obtain a shell as apache and escalate through a SUID find binary.
A Proving Grounds Linux walkthrough covering ZoneMinder SQL injection, a MySQL file write into the Apache web root, a reverse shell as www-data, and privilege escalation through a MySQL UDF.
A Proving Grounds Linux walkthrough covering authenticated Gerapy RCE, Python capability enumeration, and root access through cap_setuid.
A Proving Grounds Practice Linux walkthrough covering htmLawed command execution, runtime process monitoring, and a root-executed writable script.